aboutsummaryrefslogtreecommitdiffstats
path: root/etc/profile-a-l/funnyboat.profile
diff options
context:
space:
mode:
authorLibravatar netblue30 <netblue30@protonmail.com>2021-05-20 08:21:45 -0400
committerLibravatar netblue30 <netblue30@protonmail.com>2021-05-20 08:21:45 -0400
commiteb30ce54e7a8a75db773a1bbe762a3abdf2ccc42 (patch)
treead897bbb49cef1e4cfade7e97669c9149e78ceaa /etc/profile-a-l/funnyboat.profile
parentjailtest -> jailcheck (#4268) (diff)
downloadfirejail-eb30ce54e7a8a75db773a1bbe762a3abdf2ccc42.tar.gz
firejail-eb30ce54e7a8a75db773a1bbe762a3abdf2ccc42.tar.zst
firejail-eb30ce54e7a8a75db773a1bbe762a3abdf2ccc42.zip
new profiles
Diffstat (limited to 'etc/profile-a-l/funnyboat.profile')
-rw-r--r--etc/profile-a-l/funnyboat.profile57
1 files changed, 57 insertions, 0 deletions
diff --git a/etc/profile-a-l/funnyboat.profile b/etc/profile-a-l/funnyboat.profile
new file mode 100644
index 000000000..e4d9b018e
--- /dev/null
+++ b/etc/profile-a-l/funnyboat.profile
@@ -0,0 +1,57 @@
1# Firejail profile for default
2# This file is overwritten after every install/update
3# Persistent local customizations
4include funnyboat.local
5# Persistent global definitions
6include globals.local
7
8noblacklist ${HOME}/.funnyboat
9
10include disable-common.inc
11include disable-devel.inc
12ignore noexec /dev/shm
13include disable-exec.inc
14include allow-python2.inc
15include allow-python3.inc
16include disable-interpreters.inc
17include disable-passwdmgr.inc
18include disable-programs.inc
19# include disable-shell.inc
20include disable-write-mnt.inc
21include disable-xdg.inc
22
23mkdir ${HOME}/.funnyboat
24whitelist ${HOME}/.funnyboat
25include whitelist-common.inc
26include whitelist-runuser-common.inc
27whitelist /usr/share/funnyboat
28# Debian:
29whitelist /usr/share/games/funnyboat
30include whitelist-usr-share-common.inc
31include whitelist-var-common.inc
32
33apparmor
34caps.drop all
35ipc-namespace
36netfilter
37nodvd
38nogroups
39noinput
40nonewprivs
41noroot
42notv
43novideo
44protocol unix,inet,inet6
45seccomp
46shell none
47# tracelog
48
49disable-mnt
50private-cache
51private-dev
52private-tmp
53
54dbus-user none
55dbus-system none
56
57memory-deny-write-execute